VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 219 of 353
  • CVE-2026-12811MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.01

    A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross…

  • CVE-2026-10173MedMay 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is…

  • CVE-2026-9566MedMay 26, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipulation of the argument redirect leads to cross site scripting. The attack is…

  • CVE-2026-8195MedMay 9, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Handler. The manipulation results…

  • CVE-2026-7596MedMay 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site…

  • CVE-2026-5808MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/client.tsx of the component Onboarding Endpoint. The manipulation of the argument…

  • CVE-2026-5630MedApr 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The…

  • CVE-2026-5625MedApr 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the component WebSocket Interface. Executing a manipulation of the argument task can lead to cross site…

  • CVE-2026-5615MedApr 6, 2026
    risk 0.21cvss 4.3epss 0.01

    A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the…

  • CVE-2026-4510MedMar 21, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation…

  • CVE-2025-14691MedDec 14, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to…

  • CVE-2025-11360MedOct 7, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the file api/src/app.js of the component API. The manipulation of the argument X-Ingress-Path results in cross site scripting. The attack can be executed remotely.…

  • CVE-2025-7885MedJul 20, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument hostname/port leads to cross site scripting. The attack may…

  • CVE-2025-3841LowApr 21, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation of the argument config['template']…

  • CVE-2024-28811LowSep 30, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.

  • CVE-2024-3121LowJun 24, 2024
    risk 0.21cvss 3.3epss 0.00

    A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker to inject arbitrary commands by…

  • CVE-2022-28766LowNov 17, 2022
    risk 0.21cvss 3.3epss 0.01

    Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of…

  • CVE-2022-0282MedJan 20, 2022
    risk 0.21cvss 4.3epss 0.01

    Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2021-42754LowNov 2, 2021
    risk 0.21cvss 3.2epss 0.00

    An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.

  • CVE-2026-18682LowAug 3, 2026
    risk 0.20cvss 3.1epss 0.00

    A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting. The attack may be performed from remote. A…